syncfusion-javascript-bullet-chart

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents how to bind external data to UI components (specifically Bullet Charts) through a dataSource property, which creates a surface for indirect prompt injection if the ingested data contains malicious instructions.
  • Ingestion points: Data is ingested via the dataSource property in SKILL.md and references/data-binding-and-labels.md.
  • Boundary markers: The skill documentation in references/title-tooltip-and-interactivity.md includes an explicit security warning: "Do not place unsanitized user content inside a tooltip template."
  • Capability inventory: The skill focuses on data visualization and browser-side data fetching via fetch(); it does not include instructions for file system writes or privileged command execution.
  • Sanitization: No built-in sanitization code is provided in the examples, placing the responsibility on the implementing developer as noted in the documentation.
  • [EXTERNAL_DOWNLOADS]: The skill references and downloads legitimate library scripts from the vendor's official content delivery network.
  • Evidence: Multiple HTML examples in SKILL.md and references/getting-started.md reference scripts hosted at cdn.syncfusion.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-bullet-chart